Happy Cybersecurity Awareness Month. This year’s theme from CISA and the National Cybersecurity Alliance is “Don’t Make It Easy for Them,” and I like it. It’s about habits, not heroics.
Here’s my prediction for the next 31 days. Somewhere in your organization, a training slide is going to teach people how to spot a deepfake. Things like: watch for unnatural blinking, check whether the lips match the audio, look for blurry edges around the face, strange lighting, a hand with six fingers.
Please delete that slide.
The tells are gone
That checklist was reasonable advice a few years ago. It’s hacklore now. The artifacts it describes were limitations of early models, and the models fixed them. Every “tell” you teach is a bug report the next version already closed.
The research backs this up. In a 2025 study of 2,000 US and UK consumers, 0.1% correctly identified every real and fake image and video they were shown. Not 10%. One in a thousand.
Participants were 36% less likely to catch a fake video than a fake image, and video is exactly what an attacker brings to a call. The kicker: people stayed more than 60% confident in their answers while getting them wrong.
That’s the real problem with spot-the-fake training. It doesn’t just fail, it builds confidence nobody earned. The person who aced your deepfake quiz in October is more likely to trust their eyes in March, when a real one hits their desk and it really matters.
I’ve watched the gap close myself. I built a live deepfake for one of my talks. In January 2026 it took about 30 minutes and a lot of back-and-forth with an AI coding assistant (I wrote about that here). By April it took six minutes and one command. Zero coding either time.
The tools improve faster than anyone can update an awareness slide.
Verify the request, not the face
Stop asking “is this person real?” You’ll lose that bet. Instead, ask, “does this request follow the process?”
A deepfake is the delivery mechanism. The attack is the ask: move money, change a bank account, reset a password, send a file, keep it quiet, do it now. Those asks look the same whether they arrive by email, by phone, or on a video call with a flawless face attached. And every one of them can be verified without judging the face at all.
That means:
- Hang up and call back on a number you already had. Not one from the call, the email, or the meeting invite. And not the first number that comes up in a search.
- Use a code word for high-stakes requests, at work and at home. It’s low tech, and it works because it lives offline.
- Treat urgency as a trigger, not a reason. Pressure to skip a step is the attack. A real CEO can wait fifteen minutes.
- Require a second approver for anything over a threshold you set on purpose.
None of these need anyone to be a good judge of video. That’s the point. A control that depends on human perception fails the day the fakes get better. A control that depends on process doesn’t care how good the fakes get.
The one tell that still works
There is one pattern worth teaching, and it’s behavioral, not visual.
FinCEN’s deepfake alert to financial institutions lists red flags for remote identity checks. Two stand out to me: a customer who tries to switch communication methods mid-verification because of “technological glitches,” and a customer who declines multifactor authentication.
Let me translate that for everyone else: When someone resists verification, that’s your tell. The camera suddenly stops working. The connection is bad, can we just finish this over text. I can’t take a callback, I’m about to board a plane. I’ll send the code word later.
Real people put up with a callback. Attackers route around it. Teach people to notice the routing.
For community banks, this matters twice. Your staff get targeted with impersonations of executives and vendors, and your customers get targeted with impersonations of you and of their own families. The FBI’s 2025 Internet Crime Report counted nearly $893 million in losses tied to AI-enabled scams, the first year it tracked that category, and $7.7 billion in losses among Americans over 60. Plenty of those older customers walk into your branches. Your frontline staff are often the last people who talk to them before the wire goes out.
What to do this month
If you own awareness training this October, swap the spot-the-fake module for this:
- Show your leadership team a live deepfake. Five minutes of watching a colleague’s face on someone else’s head does more than a year of slides. Nobody leaves that room thinking they can eyeball it.
- Audit your callback control. Pull last quarter’s wire requests and payment-instruction changes. Count how many show a documented callback to a number on file. That’s your real coverage.
- Set code words. Finance team this week. Your family this weekend. Your parents the next time you call them.
- Change the message. Replace “Can you spot the fake?” with “You don’t have to. Verify the request.”
“Don’t Make It Easy for Them” is the right theme. The easiest thing you can hand an attacker is a workforce that believes it can tell real from fake by looking. Take that belief away and they’re back to fighting your process, which is a much harder fight for them.
If you want help building a verification process that holds up when you can’t trust the face on the screen, book a call: https://cal.com/vaughn-cyber-group

